If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1115 - Clipboard Data, Technique T111.

site address: attack.mitre.org/techniques/T1115 redirected to: attack.mitre.org/techniques/T1115

site title: Clipboard Data, Technique T1115 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 15 August 2026 7:32:05 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

clipboard, data, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
retrieved (65), #clipboard (63), the (61), data (42), and (32), november (22), from (22), 2018 (20), can (20), 2019 (16), april (16), 2020 (16), october (15), 2024 (15), has (15), 2017 (14), malware (13), july (13), february (13), 2025 (11), may (11), att (10), all (10), new (10), september (9), 2021 (9), threat (9), for (9), with (9), steal (9), 2022 (8), march (8), campaign (8), contents (8), enterprise (7), june (7), december (7), collect (7), capture (7), detection (6), techniques (6), used (6), august (6), 2026 (5), ics (5), mobile (5), none (5), campaigns (5), analysis (5), variant (5), panda (5), based (5), 2023 (5), that (5), 2016 (5), unit (5), agent (5), tesla (5), access (5), stored (5), collects (5), ability (5), windows (5), version (5), 2015 (4), mitre (4), use (4), january (4), rat (4), 2014 (4), operation (4), apt (4), banking (4), trojan (4), zhang (4), team (4), targets (4), research (4), machete (4), invisibleferret (4), darkgate (4), information (4), host (4), content (4), using (4), software (3), groups (3), cti (3), mitigations (3), defenses (3), sub (3), zeus (3), vermin (3), great (3), tajmahal (3), silenttrinity (3), attacks (3), rtm (3), north (3), korean (3), rokrat (3), remexi (3), spy (3), iran (3), remcos (3), paklog (3), wocao (3), symantec (3), government (3), eset (3), security (3), mispadu (3), metamorfo (3), financial (3), attack (3), konni (3), koadic (3), kimsuky (3), oilrig (3), helminth (3), grandoreiro (3), darktortilla (3), ransomware (3), darkcomet (3), cosmicduke (3), clambling (3), catchamas (3), bookworm (3), commands (3), attor (3), also (3), astaroth (3), processes (3), apt38 (3), clip (3), get (3), getclipboarddata (3), function (3), monitor (3), copy (3), compromised (3), tools (3), saved (3), module (3), openclipboard (3), macos (3), adversaries (3), corporation (2), are (2), domains (2), resources (2), reference (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), formbook (2), phishing (2), lancaster (2), cortes (2), custom (2), project (2), victims (2), systems (2), chafer (2), uses (2), espionage (2), against (2), latest (2), hacking (2), hunter (2), middle (2), eastern (2), actor (2), group (2), via (2), updates (2), chinese (2), this (2), targeting (2), institutions (2), more (2), global (2), years (2), under (2), cyber (2), platform (2), actors (2), response (2), falcone (2), organizations (2), backdoor (2), cryptocurrency (2), mining (2), chen (2), infostealer (2), spyware (2), operations (2), microsoft (2), about (2), user (2), terminal (2), context (2), chained (2), staging (2), exfiltration (2), pbpaste (2), potentially (2), collection (2), exe (2), analytic (2), description (2), name (2), technique (2), system (2), victim (2), xloader (2), contains (2), tinyzbot (2), text (2), open (2), runningrat (2), steals (2), during (2), replace (2), wallet (2), mgbot (2), melcoz (2), markirat (2), macspy (2), jrat (2), jhuhugit (2), log (2), flawedammyy (2), explosive (2), empire (2), chimneysweep (2), cadelspy (2), apt39 (2), linux (2), t1115 (2), users (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, ebach, results, gustavo, palazolo, netskope, delivered, through, emails, nart, villeneuve, randi, eitzman, sandor, nemes, tyler, dean, google, cloud, significant, distribution, impacting, south, korea, quasar, ukraine, cylance, cleaver, sophisticated, framework, byt3bl33d3r, sherstobitoff, saavedra, morales, gold, dragon, widens, olympics, gains, permanent, presence, duncan, harbison, russian, language, malspam, pushing, redaman, faou, boutin, read, manual, guide, cash, grunzweig, adair, bluelight, special, inkysquid, deploys, legezo, foreign, diplomatic, entities, exploit, klijnsma, leverages, spear, rats, turkish, defense, contractors, sudeep, singh, mustang, arsenal, corklog, splatcloak, dantzig, schamper, shining, light, one, china, hidden, crambus, advertisement, discounted, unhappy, meal, daggerfly, telecoms, company, africa, facundo, muñoz, evasive, delivers, popular, casbaneiro, peculiarities, affects, brazil, mexico, another, customers, countries, tetrade, brazilian, goes, ferocious, kitten, covert, surveillance, patrick, wardle, mac, kaspersky, just, got, sharper, venezuelan, rascagneres, radar, magius, varadharajan, krishnasamy, aditya, sood, reconnaissance, control, operational, blueprint, kamluk, gostev, adwind, cross, playbook, viewer, seongsu, park, pyongyang, your, payroll, rise, remote, workers, west, employers, seeking, employment, two, job, related, bear, hallmarks, matej, havranek, deceptivedevelopment, freelance, developers, esentire, tru, bored, beavertail, yacht, club, lazarus, lure, lee, saudi, arabian, deliver, abramov, now, banks, spain, institute, profiling, ta505, continues, sector, intelligence, volatile, cedar, schroeder, warner, nelson, github, powershellempire, secureworks, counter, mcgraw, black, basta, drops, zbot, adi, zeligson, rotem, kerner, enter, kujawa, you, dirty, part, secure, labs, cosmu, twist, miniduke, base, dropbox, lunghi, uncovering, drbcontrol, jenkins, roadsweep, likely, iranian, conducts, politically, motivated, disruptive, activity, albanian, balanza, attackers, back, door, threats, robert, mike, scott, juan, model, modular, architecture, hromcova, tor, communications, meet, fantasy, creature, salem, legitimate, antivirus, passwords, personal, reveal, heightened, ambitions, fireeye, usual, suspects, arsene, oil, gas, spearphishing, drop, advance, historic, opec, deal, depth, net, agenttesla, brumaghin, old, dog, tricks, analysing, rtf, distributing, loki, pyrebox, rvrsh3ll, operating, empyre, maljic, malicious, ruby, gems, cisa, alert, aa21, 200b, state, sponsored, observed, ttps, jasongerend, references, xclip, xsel, buffers, outside, especially, when, gzip, base64, network, curl, scp, an0967, pbcopy, without, sessions, linked, launch, agents, staged, an0966, utilities, non, interactive, abnormal, parent, an0965, anomalous, det0341, strategy, type, cannot, easily, mitigated, preventive, controls, since, abuse, features, hook, watch, pastes, s0330, s1207, s0257, functionality, s0004, infected, s0467, forms, gettext, s0692, code, s0253, s0148, extract, s0240, s0375, modifies, s0332, monitored, extracted, s1233, collected, plaintext, c0014, g0049, bitcoin, s1122, s1146, hijack, monitoring, replacing, attacker, s0455, s0530, s0652, s0282, hijacks, creating, overlapped, window, listens, keyboard, events, s0409, had, feature, s0356, retrieve, current, s0250, g0094, s0283, accesses, screenshot, converts, jpg, image, s0044, stolen, python, pyperclip, captured, paste, s1245, executable, s0170, s0531, s0381, wrapper, s0569, harvest, both, s0363, download, stealer, s1066, starts, thread, execution, captures, logs, predefined, file, s1111, s0334, copies, exfiltrates, every, seconds, s0050, store, s0660, s1149, s0261, s0454, its, kblogger, dll, s1226, plugin, apis, s0438, libraries, s0373, capable, stealing, g0087, called, keylime, g0082, s0331, procedure, examples, live, permalink, last, modified, created, platforms, tactic, have, such, grab, example, additionally, then, their, transmitted, manipulation, copying, within, between, applications, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, started, detections,


Text of the page (random words):
clipboard data technique t1115 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise clipboard data clipboard data adversaries may collect data stored in the clipboard from users copying information within or between applications for example on windows adversaries can access clipboard data by using clip exe or get clipboard 1 2 3 additionally adversaries may monitor then replace users clipboard with their data e g transmitted data manipulation 4 macos and linux also have commands such as pbpaste to grab clipboard contents 5 id t1115 sub techniques no sub techniques ⓘ tactic collection ⓘ platforms linux windows macos version 1 2 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description s0331 agent tesla agent tesla can steal data from the victim s clipboard 6 7 8 9 g0082 apt38 apt38 used a trojan called keylime to collect data from the clipboard 10 g0087 apt39 apt39 has used tools capable of stealing contents of the clipboard 11 s0373 astaroth astaroth collects information from the clipboard by using the openclipboard and getclipboarddata libraries 12 s0438 attor attor has a plugin that collects data stored in the windows clipboard by using the openclipboard and getclipboarddata apis 13 s1226 bookworm bookworm has used its kblogger dll module to steal data saved to the clipboard 14 s0454 cadelspy cadelspy has the ability to steal data from the clipboard 15 s0261 catchamas catchamas steals data stored in the clipboard 16 s1149 chimneysweep chimneysweep can capture content from the clipboard 17 s0660 clambling clambling has the ability to capture and store clipboard data 18 19 s0050 cosmicduke cosmicduke copies and exfiltrates the clipboard contents every 30 seconds 20 s0334 darkcomet darkcomet can steal data from the clipboard 21 s1111 darkgate darkgate starts a thread on execution that captures clipboard data and logs it to a predefined log file 22 23 s1066 darktortilla darktortilla can download a clipboard information stealer module 24 s0363 empire empire can harvest clipboard data on both windows and macos systems 25 s0569 explosive explosive has a function to use the openclipboard wrapper 26 s0381 flawedammyy flawedammyy can collect clipboard data 27 s0531 grandoreiro grandoreiro can capture clipboard data from a compromised host 28 s0170 helminth the executable version of helminth has a module to log clipboard contents 29 s1245 invisibleferret invisibleferret has stolen data from the clipboard using the python project pyperclip 30 31 32 invisibleferret has also captured clipboard contents during copy and paste operations 33 s0044 jhuhugit a jhuhugit variant accesses a screenshot saved in the clipboard and converts it to a jpg image 34 s0283 jrat jrat can capture clipboard data 35 g0094 kimsuky kimsuky has the ability to steal data from the clipboard 36 s0250 koadic koadic can retrieve the current content of the user clipboard 37 s0356 konni konni had a feature to steal data from the clipboard 38 s0409 machete machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events 39 40 s0282 macspy macspy can steal clipboard contents 41 s0652 markirat markirat can capture clipboard content 42 s0530 melcoz melcoz can monitor content saved to the clipboard 43 s0455 metamorfo metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker s 44 45 s1146 mgbot mgbot can capture clipboard data 46 47 s1122 mispadu mispadu has the ability to capture and replace bitcoin wallet data in the clipboard on a compromised host 48 g0049 oilrig oilrig has used infostealer tools to copy clipboard data 49 c0014 operation wocao during operation wocao threat actors collected clipboard data in plaintext 50 s1233 paklog paklog has monitored and extracted clipboard contents 51 s0332 remcos remcos steals and modifies data from the clipboard 52 53 s0375 remexi remexi collects text from the clipboard 54 s0240 rokrat rokrat can extract clipboard data from a compromised host 55 s0148 rtm rtm collects data from the clipboard 56 57 s0253 runningrat runningrat contains code to open and copy data from the clipboard 58 s0692 silenttrinity silenttrinity can monitor clipboard text and can use system windows forms clipboard gettext to collect data from the clipboard 59 s0467 tajmahal tajmahal has the ability to steal data from the clipboard of an infected host 60 s0004 tinyzbot tinyzbot contains functionality to collect information from the clipboard 61 s0257 vermin vermin collects data stored in the clipboard 62 s1207 xloader xloader can collect data stored in the victim s clipboard 63 64 s0330 zeus panda zeus panda can hook getclipboarddata function to watch for clipboard pastes to collect 65 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0341 clipboard data access with anomalous context an0965 detection of clipboard access via os utilities e g clip exe get clipboard by non interactive or abnormal parent processes potentially chained with staging or exfiltration commands an0966 detection of pbpaste pbcopy clipboard access by processes without terminal sessions or linked to launch agents potentially staged for collection an0967 detection of xclip or xsel access to clipboard buffers outside of user terminal context especially when chained to staging gzip base64 or network exfiltration curl scp references microsoft n d about the clipboard retrieved march 29 2016 microsoft jasongerend et al 2023 february 3 clip retrieved june 21 2022 cisa 2021 august 20 alert aa21 200b chinese state sponsored cyber operations observed ttps retrieved june 21 2022 maljic t 2020 april 16 mining for malicious ruby gems retrieved october 15 2022 rvrsh3ll 2016 may 18 operating with empyre retrieved july 12 2017 brumaghin e et al 2018 october 15 old dog new tricks analysing new rtf based campaign distributing agent tesla loki with pyrebox retrieved november 5 2018 zhang x 2018 april 05 analysis of new agent tesla spyware variant retrieved november 5 2018 zhang x 2017 june 28 in depth analysis of a new variant of net malware agenttesla retrieved november 5 2018 arsene l 2020 april 21 oil gas spearphishing campaigns drop agent tesla spyware in advance of historic opec deal retrieved may 19 2020 fireeye 2018 october 03 apt38 un usual suspects retrieved november 17 2024 symantec 2018 february 28 chafer latest attacks reveal heightened ambitions retrieved may 22 2020 salem e 2019 february 13 astaroth malware uses legitimate os and antivirus processes to steal passwords and personal data retrieved april 17 2019 hromcova z 2019 october at commands tor based communications meet attor a fantasy creature and also a spy platform retrieved may 6 2020 robert falcone mike scott juan cortes 2015 november 10 bookworm trojan a model of modular architecture retrieved july 21 2025 symantec security response 2015 december 7 iran based attackers use back door threats to spy on middle eastern targets retrieved april 17 2019 balanza m 2018 april 02 infostealer catchamas retrieved november 17 2024 jenkins l at al 2022 august 4 roadsweep ransomware likely iranian threat actor conducts politically motivated disruptive activity against albanian government organizations retrieved august 6 2024 lunghi d et al 2020 february uncovering drbcontrol retrieved november 12 2021 chen t and chen z 2020 february 17 clambling a new backdoor base on dropbox retrieved november 12 2021 f secure labs 2014 july cosmicduke cosmu with a twist of miniduke retrieved july 3 2014 kujawa a 2018 march 27 you dirty rat part 1 darkcomet retrieved november 6 2018 adi zeligson rotem kerner 2018 november 13 enter the darkgate new cryptocurrency mining and ransomware campaign retrieved february 9 2024 mcgraw t 2024 december 4 black basta ransomware campaign drops zbot darkgate and custom malware retrieved december 9 2024 secureworks counter threat unit research team 2022 august 17 darktortilla malware analysis retrieved november 3 2022 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 threat intelligence and research 2015 march 30 volatile cedar retrieved february 8 2021 financial security institute 2020 february 28 profiling of ta505 threat group that continues to attack the financial sector retrieved july 14 2022 abramov d 2020 april 13 grandoreiro malware now targeting banks in spain retrieved november 12 2020 falcone r and lee b 2016 may 26 the oilrig campaign attacks on saudi arabian organizations deliver helminth backdoor retrieved may 3 2017 esentire threat response unit tru 2024 november 14 bored beavertail invisibleferret yacht club a lazarus lure pt 2 retrieved october 17 2025 matej havranek 2025 february 20 deceptivedevelopment targets freelance developers retrieved october 17 2025 unit 42 2023 november 21 hacking employers and seeking employment two job related campaigns bear hallmarks of north korean threat actors retrieved october 17 2025 seongsu park 2024 november 4 from pyongyang to your payroll the rise of north korean remote workers in the west retrieved october 17 2025 unit 42 2017 december 15 unit 42 playbook viewer retrieved december 20 2017 kamluk v gostev a 2016 february adwind a cross platform rat retrieved april 23 2019 varadharajan krishnasamy aditya k sood 2025 july 29 from reconnaissance to control the operational blueprint of kimsuky apt for cyber espionage retrieved april 18 2026 magius j et al 2017 july 19 koadic retrieved september 27 2024 rascagneres p 2017 may 03 konni a malware under the radar for years retrieved november 5 2018 eset 2019 july machete just got sharper venezuelan government institutions under attack retrieved september 13 2019 kaspersky global research and analysis team 2014 august 20 el machete retrieved september 13 2019 patrick wardle n d mac malware of 2017 retrieved september 21 2018 great 2021 june 16 ferocious kitten 6 years of covert surveillance in iran retrieved september 22 2021 great 2020 july 14 the tetrade brazilian banking malware goes global retrieved november 9 2020 zhang x 2020 february 4 another metamorfo variant targeting customers of financial institutions in more countries retrieved july 30 2020 eset research 2019 october 3 casbaneiro peculiarities of this banking trojan that affects brazil and mexico retrieved september 23 2021 facundo muñoz 2023 april 26 evasive panda apt group delivers malware via updates for popular chinese software retrieved july 25 2024 threat hunter team 2023 april 20 daggerfly apt actor targets telecoms company in africa retrieved july 25 2024 eset security 2019 november 19 mispadu advertisement for a discounted unhappy meal retrieved march 13 2024 symantec threat hunter team 2023 october 19 crambus new campaign targets middle eastern government retrieved november 27 2024 dantzig m v schamper e 2019 december 19 operation wocao shining a light on one of china s hidden hacking groups retrieved october 8 2020 sudeep singh 2025 april 16 latest mustang panda arsenal paklog corklog and splatcloak p2 retrieved september 12 2025 klijnsma y 2018 january 23 espionage campaign leverages spear phishing rats against turkish defense contractors retrieved november 6 2018 zhang x 2024 november 8 new campaign uses remcos rat to exploit victims retrieved april 16 2026 legezo d 2019 january 30 chafer used remexi malware to spy on iran based foreign diplomatic entities retrieved april 17 2019 cash d grunzweig j adair s lancaster t 2021 august 25 north korean bluelight special inkysquid deploys rokrat retrieved october 1 2021 faou m and boutin j 2017 february read the manual a guide to the rtm banking trojan retrieved march 9 2017 duncan b harbison m 2019 january 23 russian language malspam pushing redaman banking malware retrieved june 16 2020 sherstobitoff r saavedra morales j 2018 february 02 gold dragon widens olympics malware attacks gains permanent presence on victims systems retrieved june 6 2018 byt3bl33d3r n d silenttrinity retrieved september 12 2024 great 2019 april 10 project tajmahal a sophisticated new apt framework retrieved october 14 2019 cylance 2014 december operation cleaver retrieved september 14 2017 lancaster t cortes j 2018 january 29 vermin quasar rat and custom malware used in ukraine retrieved july 5 2018 nart villeneuve randi eitzman sandor nemes tyler dean google cloud 2017 october 5 significant formbook distribution campaigns impacting the u s and south korea retrieved march 11 2025 gustavo palazolo netskope 2022 march 11 new formbook campaign delivered through phishing emails retrieved march 11 2025 ebach l 2017 june 22 analysis results of zeus variant panda retrieved november 5 2018 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 91 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-91


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1115
X-GitHub-Request-Id 67BE:175124:1FF36FA:202102B:6A8015F4
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sat, 15 Aug 2026 07:32:05 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290028-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786779125.433787,VS0,VE99
Vary Accept-Encoding
X-Fastly-Request-ID de4dcd27882820bfb260706a6c6a2224f50721dc
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1115/
access-control-allow-origin *
expires Sat, 15 Aug 2026 07:42:05 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id C74C:1AF657:1FCE057:1FFBA40:6A8015F5
x-github-edge-region fra
accept-ranges bytes
date Sat, 15 Aug 2026 07:32:05 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290026-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786779126.570570,VS0,VE96
vary Accept-Encoding
x-fastly-request-id c565c90f226bf733ef7b7c9d0de3d4a8e0d2feae
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-1d939
expires Sat, 15 Aug 2026 07:42:05 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 7E74:7640F:1FF6E56:2024785:6A8015F5
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 15 Aug 2026 07:32:05 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290026-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786779126.679416,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 2a772ab856c26d7c0c1aef3180cc38e11efc6245
content-length 22913

Meta Tags

title="Clipboard Data, Technique T1115 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size22913
load time (s)0.846328
redirect count2
speed download27083
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"